Versions of concat-stream before 1.5.2 are vulnerable to memory exposure if user provided input is passed into write(). Versions <1.3.0 are not affected due to not using unguarded Buffer constructor. External Reference: https://nodesecurity.io/advisories/597 Upstream patch: https://github.com/maxogden/concat-stream/pull/47/commits/3e285ba5e5b10b7c98552217f5c1023829efe69e
Created nodejs-concat-stream tracking bugs for this issue: Affects: epel-all [bug 1577723] Affects: fedora-26 [bug 1577724]
*** This bug has been marked as a duplicate of bug 1432987 ***